SV-251738r919225_rule
V-251738
SRG-NET-000089-FW-000019
T0FW-3X-000011
CAT II
10
(Optional) From an NSX-T Edge Gateway shell, run the following command(s) to clear any existing incorrect logging-servers:
> clear logging-servers
From an NSX-T Edge Node shell, run the following command(s) to configure a primary and backup tls syslog server:
> set logging-server <server-ip or server-name> proto tls level info serverca ca.pem clientca ca.pem certificate cert.pem key key.pem
From an NSX-T Edge Node shell, run the following command(s) to configure a li-tls syslog server:
> set logging-server <server-ip or server-name> proto li-tls level info serverca root-ca.crt
Note: If using the protocols TLS or LI-TLS to configure a secure connection to a log server, the server and client certificates must be stored in /var/vmware/nsx/file-store/ on each NSX-T Edge Gateway appliance.
Note: Configure the syslog or SNMP server to send an alert if the events server is unable to receive events from the NSX-T and also if DoS incidents are detected. This is true if the events server is STIG compliant.
From an NSX-T Edge Node shell hosting the Tier-0 Gateway, run the following command(s):
> get logging-servers
If any configured logging-servers are not configured with protocol of "li-tls" or "tls" and level of "info", this is a finding.
If no logging-servers are configured, this is a finding.
Note: This check must be run from each NSX-T Edge Node hosting the Tier-0 Gateway, as they are configured individually.
V-251738
False
T0FW-3X-000011
From an NSX-T Edge Node shell hosting the Tier-0 Gateway, run the following command(s):
> get logging-servers
If any configured logging-servers are not configured with protocol of "li-tls" or "tls" and level of "info", this is a finding.
If no logging-servers are configured, this is a finding.
Note: This check must be run from each NSX-T Edge Node hosting the Tier-0 Gateway, as they are configured individually.
M
5451